ALT-PU-2019-2936-1
Closed vulnerabilities
Published: 2018-09-06
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-1000667
NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..
Severity: MEDIUM (5.5)
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
Published: 2018-09-07
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-16517
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file.
Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
- openSUSE-SU-2020:0954
- openSUSE-SU-2020:0954
- openSUSE-SU-2020:0952
- openSUSE-SU-2020:0952
- http://packetstormsecurity.com/files/152566/Netwide-Assembler-NASM-2.14rc15-Null-Pointer-Dereference.html
- http://packetstormsecurity.com/files/152566/Netwide-Assembler-NASM-2.14rc15-Null-Pointer-Dereference.html
- https://bugzilla.nasm.us/show_bug.cgi?id=3392513
- https://bugzilla.nasm.us/show_bug.cgi?id=3392513
- https://fakhrizulkifli.github.io/CVE-2018-16517.html
- https://fakhrizulkifli.github.io/CVE-2018-16517.html
- 46726
- 46726
Published: 2018-11-12
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-19216
Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.
Severity: HIGH (7.8)
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- openSUSE-SU-2020:0954
- openSUSE-SU-2020:0954
- openSUSE-SU-2020:0952
- openSUSE-SU-2020:0952
- https://bugzilla.nasm.us/show_bug.cgi?id=3392424
- https://bugzilla.nasm.us/show_bug.cgi?id=3392424
- https://repo.or.cz/nasm.git/commitdiff/9b7ee09abfd426b99aa1ea81d19a3b2818eeabf9
- https://repo.or.cz/nasm.git/commitdiff/9b7ee09abfd426b99aa1ea81d19a3b2818eeabf9